Live data from Hacker News

Uncorrectable freedom and security issues on x86 platforms (2016)

decentralize.today

61–70 of 141 posts

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#61

Earlier quoted context omitted.

> there is no suggestions for how to secure and harden devices without refining these trusted computing techniques. We need to harden these devices. Because the thing you are asking for is not possible. You have a bad premise: > And I just don't understand how anyone can maintain that farce when the last year has shown that it's a genuine challenge even for the US FBI to unlock a mobile device without the owners say-…

They don't need physical access to compromise your firmware. I thought that was one of the things the original article claimed, at least. The EMs firmware can be updated remotely if the system is plugged in (whether powered on or not).

Yes, but it would clearly be possible to create hardware without that special misfeature.

What isn't possible is to create hardware that can protect you against an attacker with unrestricted physical access.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#62

I was struck by the following passage: >including Secure Boot, which even now requires FOSS users to purchase a license from Microsoft to boot FOSS on affected machines that lack an appropriate Secure Boot override." Can someone explain this to me, would this be for instance be Lenovo laptops making a deal with Microsoft since Windows is the default OS installed on these laptops? Is Microsoft mandating all OEMs/hardw…

I tend to think the SecureBoot isn't really a grand conspiracy. You can't realistically expect end users to be in charge of keys. So MS does what's best for itself. The problem is with poor implementations by vendors that don't support self signing, and in some cases don't even support disabling secure boot.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#63
Want complete software freedom? How about the MIPS chips the Russian military uses[1]? Those don't have an NSA back door. Sucks you can't really buy them as they are only made for use in Russian military and government applications.

"Last year, the Russian government announced that it doesn't want to rely on Intel and AMD chips from the U.S. anymore and will focus more on using homegrown chips from Russia."

[1] http://www.tomshardware.com/news/baikal-t1-mips-cpu-omnishie...

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#64
post #16

Earlier quoted context omitted.

Is Microsoft mandating all OEMs/hardware vendors to configure secure boot with a MS signing key? Basically yes; it's required to get the Windows sticker. I haven't heard that MS charges money to sign bootloaders, though.

Thanks, I have to wonder how much of bureaucratic headache that is to get your bootloader signed.

James Bottomley navigated the bureaucracy and lived to tell about it: https://blog.hansenpartnership.com/adventures-in-microsoft-u...

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#65

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

Try using Intel ME. Than come back and tell us that's a tool for mass surveillance. If you think there's a evil NSA front for this type of stuff -- its Absolute Software. Their bits have been embedded in most BIOS packages since the 90s, and nobody has heard of them.

Thanks. https://www.absolute.com/en/about/persistence

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#67
post #8

Isn't it sci-fi-level incredible, and frankly both scary and shady, that every modern x86 CPU has this forced sub-ring-0 control program? And that the CPU vendors apparently go to extreme lengths in hiding its functionality? Why would even large vendors like Apple or Dell agree to this? The 30-minute timeout is particularly mischievous. It's like they REALLY want to slow down any effort at patching out the ME. Are we…

It's the kind of stuff the boring, slow-moving, TCG group were talking about long ago for improved DRM and security. Then they advertised their backdoors publicly as vPro while people here argued why Intel rand was trustworthy (lol). They sold that as management benefit for enterprises. Eventually those gradual changes got to the current point.

Although I recommend switching off x86, I don't buy the claim that we cant do another x86 without backdoors. For one, Intel or AMD might do a "semi-custom" design without one for a price. Second, Centaur has long been the 3rd player in x86 for low power stuff sold by VIA. They'd probably do a high-performance design if incentivized. Third, many x86 players showed up over time that simply failed in market or were acquired. Nothing stopping another unless there's a legal restriction Im unaware of.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#68

Earlier quoted context omitted.

NSA 100% . Some time around 10 years ago governments decided the internet was too "dangerous" to be free. Arab spring cemented that into their minds, and now a bastion of free thought has become the worlds biggest spying apparatus.

Please. While no-doubt the NSA take advantage of this probably-insecure privileged processor, I seriously doubt they were behind it. Secure boot is an obvious business need and Intel and AMD clearly implemented it in the laziest way possible. And by laziest I mean: nobody is going to argue with you in a meeting if you say "we don't need to release the source code for this". Seriously, anyone who has actually worked i…

We're not talking about secure boot, we're talking about Intel Management engine, which is a totally different story. You do not need ME at all to implement Secure Boot feature. Actually, no one really knows what Intel ME is doing, and _that_ is a huge problem.

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#69

>Both serve effectively the same purpose; to ensure that the physical owner of the machine never has full control of said machine. That is the end-result, yes, but that wasn't the purpose: the purpose was to allow companies to keep track of their laptops--to remotely push out firmware updates, to inventory the hardware/asset list, etc. It was a convenience feature, essentially. Of course, the end-result, as stated, i…

Nah, that wasn't the purpose unless Im misremembering. It came later as a selling point. It started in initiatives such as Trusted Computing Group where these companies agreed on technologies to control what runs on the PC for security and DRM purposes. Featured regular, secret meetings on top of the public ones.They took lots of flak when DRM goals got press attention. That they're just helping companies manage stuff or users fix computers sounds much more pleasant. They also made sure it was true by adding those features. ;)

Re: Uncorrectable freedom and security issues on x86 platforms (2016)

#70
post #26

I'm trying to understand all of this and especially the threats to privacy, control of my computing hardware, and data security. I read about some new hard/software for secure boot , etc., but don't recall all the details now. So, for a shorter approach, suppose I just buy a processor from AMD, a motherboard from ASUS, hard disk drives from Western Digital, etc., and plug it all together for myself. So, then I'm the…

Do you still work at Fedex in Memphis? If so, we're in same vicinity. Maybe we have lunch some time and Ill tell you all about the various subversions going on. :)
Post reply on HN